Description
A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.
Published: 2026-07-16
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write vulnerability exists in Lenovo BIOS firmware that, if triggered by a local privileged user, allows execution of code in System Management Mode. The flaw is classified as CWE‑787 and can grant an attacker BIOS‑level control, effectively providing unilateral system compromise over the affected machine.

Affected Systems

The vulnerability impacts many Lenovo laptop models listed by Lenovo, including IdeaPad 5 and 3 series, Lenovo V14/V15, ThinkBook 16p and Plus series, Yoga 9 and Yoga Pro models, among others. No specific firmware version numbers are supplied; any BIOS prior to the release detailed in Lenovo's support advisory is considered vulnerable.

Risk and Exploitability

The CVSS score of 6.8 denotes moderate severity, while the EPSS score of less than 1% indicates a currently low likelihood of exploitation. The flaw requires local privileged access, implying that the attack vector is a physically present user with administrative rights or an exploit that achieves local privilege escalation. Once exploited, the attacker gains full control via System Management Mode, and the vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on July 31, 2026 at 01:36 UTC.

Remediation

Vendor Solution

Update to the version (or newer) indicated for your model in the Product Impact section of the advisory - https://support.lenovo.com/us/en/product_security/LEN-220440


OpenCVE Recommended Actions

  • Update the BIOS firmware to the latest version available for your model, as described in Lenovo’s Product Impact section of the advisory
  • Set a BIOS administrator password to prevent unauthorized firmware modifications
  • Restrict physical access to the device and enforce strong user authentication to mitigate local privileged compromise

Generated by OpenCVE AI on July 31, 2026 at 01:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Lenovo BIOS Out-of-Bounds Write Leading to Local Privilege Escalation

Tue, 28 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Lenovo BIOS Enables Local Privilege Escalation

Sun, 26 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Lenovo BIOS Enables Local Privilege Escalation

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Potential Out of Bounds Write in BIOS Enabling Privileged Code Execution in System Management Mode

Fri, 17 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Potential Out of Bounds Write in BIOS Enabling Privileged Code Execution in System Management Mode

Thu, 16 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-07-16T17:31:54.634Z

Reserved: 2026-06-01T19:55:19.225Z

Link: CVE-2026-10589

cve-icon Vulnrichment

Updated: 2026-07-16T17:22:10.139Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:45:06Z

Weaknesses